Hi team,
I would like to know if there is a way to help me with wazuh.
I have separated my index to put different lifecycle policy but I have some issues with my events.
I am currently facing some issues with rsyslog events. I have recently added proxy's events with rsyslog to retrieve these events in wazuh security events and my proxy is generating a lot of events.
After configuring rsyslog, wazuh reported this event to me:
full_log : The average number of logs between 11:00 and 12:00 is 39813. We have reached 99534.They show up in the "wazuh-archives*" index without any
rule.id or rule.level, but I want to put them in my own index called "wazuh-alerts-4.x-proxy*".
The same goes for my postfix events for my Debian mail server. My postfix events from "/var/log/maillog" show up in archives, but not in my own "wazuh-alerts-4.x-mail*" index without a
rule.id or rule.level.
I'd like to know how to deal with this because I'm lost these days and it's the last big thing to do for this project.
Is there a way to create a rule to help wazuh with these logs and put them in the right index?
Is there a way to reduce the amount of logs with anti flooding in syslog to avoid the event syslog?
For more information, I'm back at work this Thursday. Waiting, I share you some configuration file to make this clearer.
Thanks in advance for your help.